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DETAILED ACTION 

Response to Amendment 

1 . Applicant's amendment filed 03 June 2008 amends claim 1 . Claim 2 has been cancelled. 
Applicant's amendment has been fully considered and entered. 

Response to Arguments 

2. Applicant's argument that Rogaway does not disclose "a first mask value and a second 
mask value that are not identical," has been fully considered and is persuasive. Therefore, the 
rejection has been withdrawn. However, upon further consideration, a new ground(s) of 
rejection is made in view of Jutla, U.S. Patent No. 7,093,126. 

3 . Applicant alleges, "Any proposed modification to Rogaway would render the teachings 
of Rogaway unsatisfactory for its intended purposes." This allegation is completely unsupported 
by any evidence. Nothing that has been presented by Applicant supports their contention that 
any proposed modification to Rogaway would render the teachings unsatisfactory. 

4. Utilizing more than one cryptographic key in Rogaway would hardly render the teachings 
unsatisfactory for its intended purposes. The security benefits of utilizing multiple keys are well 
recognized by those of ordinary skill in the art. In addition, utilizing more than one cryptographic 
key does not change the principle operation, because all aspects of the disclosure remain the 
same with the exception of using different keys for different cryptographic operations. 

5. Applicant argues, "any modification away from that single value key frustrates the 
intended purpose of having the most efficient possible system with modest memory requirements 
and limiting processing capability." This is not persuasive because storing an extra cryptographic 
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key would not frustrate the memory requirements of the disclosed system of Rogaway. Typical 
block cipher keys are 64 bits in length. 

6. Applicant argues, "a concatenation operation is very different from an XOR operation in 
both form and result." In response, Applicant has misinterpreted the application of the reference. 
The summation of the XOR is meant to read on the claimed concatenation. The Examiner never 
stated that the XOR operation itself was intended to meet the claimed concatenation, but instead 
said that it was the XOR-sum. 

Claim Rejections - 35 USC § 112 

7. The following is a quotation of the first paragraph of 35 U.S.C. 112: 

The specification shall contain a written description of the invention, and of the manner and process of making 
and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it 
pertains, or with which it is most nearly connected, to make and use the same and shall set forth the best mode 
contemplated by the inventor of carrying out his invention. 

8. Claims 1,3-11 are rejected under 35 U.S.C. 1 12, first paragraph, as failing to comply 
with the written description requirement. The claim(s) contains subject matter which was not 
described in the specification in such a way as to reasonably convey to one skilled in the relevant 
art that the inventor(s), at the time the application was filed, had possession of the claimed 
invention. The claims have been amended to require, "whitening the at least one encrypted 
message block with a second mask value, which is not identical to the first mask value," which is 
not supported by the specification. To the contrary, the specification (Page 5, line 15) actually 
states that "the first and second mask values being equal." In addition, original claim 5 also 
stated that the first and second masks were equal. Therefore, it is clear that the amendments are 
wholly unsupported by the specification. 

Claim Rejections - 35 USC §103 
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9. The following is a quotation of 35 U.S.C. 103(a) which forms the basis for all 
obviousness rejections set forth in this Office action: 

(a) A patent may not be obtained though the invention is not identically disclosed or described as set forth in 
section 102 of this title, if the differences between the subject matter sought to be patented and the prior art are 
such that the subject matter as a whole would have been obvious at the time the invention was made to a person 
having ordinary skill in the art to which said subject matter pertains. Patentability shall not be negatived by the 
manner in which the invention was made. 

10. The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 
(1966), that are applied for establishing a background for determining obviousness under 35 
U.S.C. 103(a) are summarized as follows: 

1 . Determining the scope and contents of the prior art. 

2. Ascertaining the differences between the prior art and the claims at issue. 

3. Resolving the level of ordinary skill in the pertinent art. 

4. Considering objective evidence present in the application indicating obviousness 
or nonobviousness. 

11. Claims 1,3-11 are rejected under 35 U.S.C. 103(a) as being unpatentable over Rogaway, 
in view of Schneier, and further in view of Jutla, U.S. Patent No. 7,093,126. Referring to claims 
1,11, Rogaway discloses encrypting a message by exclusive or'ing a block of the message with 
a corresponding block of a generated value (Page 5, M[i] it? Z[i]), which meets the limitation of 
whitening at least one message block with a first mask value. The result of that exclusive or 
operation is encrypted (Page 5) using a block cipher (Page 4), which meets the limitation of 
encrypting the at least one whitened message block using a block cipher and a first key. The 
result of the encryption is the exclusive or'ed with a corresponding block of the generated value 
(Page 5), which meets the limitation of whitening the at least one encrypted message block with 
a second mask value to generate at least one corresponding output ciphertext block. Rogaway 
discloses that the corresponding block of the generated value is generated based on the XOR of 
an encrypted nonce (Page 5, R) and an encrypted value (Page 5, L), which meets the limitation of 
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the first mask value is computed by applying a XOR function to a first value derived from a 
nonce value and a second value derived from encrypting a third value using the block cipher and 
a key, wherein the second mask value is computed by applying a XOR function to a fourth value 
derived from the nonce value and a fifth value derived from encrypting a sixth value using the 
block cipher and a key. Rogaway does not specify that the key used to encrypt the value to 
generate the 'L' (Page 5) is different than the key used to encrypt M[i] (B Z[i] (Page 5). 
However, it would have been obvious to one of ordinary skill in the art at the time the invention 
was made to use multiple keys in the encryption algorithm in order to enhance the strength of the 
encryption algorithm by making the algorithm more difficult to break. Using only a single 
encryption key is easier break than using multiple because an attacker would only need to 
discover the one key as opposed to having to discover every key that is used in the encryption 
algorithm. Rogaway also does not disclose applying a substitution function to the result of the 
XOR function on L and R. However, it would have been obvious to one of ordinary skill in the 
art at the time the invention was made to perform a substitution function on the result of the 
XOR function on L and R because substitution operations are an important part of block cipher 
algorithms that give them security as taught by Schneier (Page 275). Rogaway does not disclose 
utilizing different mask values. Jutla discloses a similar block ciphering system wherein in one 
embodiment identical masks are applied to both the outputs and inputs of the cipher blocks (See 
Jutla, Figure 10 & Col. 5, lines 29-46), which is similar to the system described by Rogaway 
(Page 5). In a different embodiment, Jutla discloses applying the preceding cipher block out to 
the block cipher input and the mask to the cipher block output (See Jutla: Figure 5 & Col. 4, lines 
7-23), which meets the limitation of whitening the at least one encrypted message block with a 
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second mask value, which is not identical to the first mask value. It would have been obvious to 
one of ordinary skill in the art at the time the invention was made to utilize the alternative 
embodiment described in Jutla in Rogaway because such a modification would have been 
obvious and within the skill of one skilled in the art and would have yielded predictable results 
as taught by Jutla (Col. 5, lines 56-62). 

Referring to claim 3, Rogaway discloses that to compute the R value, the nonce is XOR'd 
with L and the result of the XOR function is encrypted with key K (Page 5), which meets the 
limitation of the first and fourth values derived from the nonce value are permutations of a binary 
value computed by encrypting the nonce value using the block cipher and the first key. 

Referring to claim 4, Rogaway discloses that the L value is generated by encrypted a 
finite string (Page 5), but does not disclose that the finite string is randomly generated. It would 
have been obvious to one of ordinary skill in the art at the time the invention was made to 
randomly generated the finite string used to calculate the L value in Rogaway such that the finite 
string would be unpredictable, thus increasing the security of cryptographic algorithm as taught 
by Schneier (Page 45). 

Referring to claim 5, Rogaway discloses encrypting a message by exclusive or'ing a 
block of the message with a corresponding block of a generated value (Page 5, M[i] Z[i]). The 
result of that exclusive or operation is encrypted (Page 5) using a block cipher (Page 4). The 
result of the encryption is the exclusive or'ed with a corresponding block of the generated value 
(Page 5), which meets the limitation of the steps of whitening each comprise the step of applying 
a XOR function. 
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Referring to claim 6, Rogaway discloses that each message blocks is concatenated (Page 
5, checksum generation function), which meets the limitation of applying a XOR function to all 
message blocks of a message to compute a XOR-sum. The checksum is then XOR'd with Z[m] 
(Page 5, calculation of value T'), which meets the limitation of applying a third mask value to 
the XOR-sum. The result of the XOR function is then encrypted (Page 5, calculation of value 
'T'), which meets the limitation of encrypting the masked XOR-sum using the block cipher and 
the first key. Rogaway does not disclose XOR'ing the result of the encryption with a value. 
However, it would have been obvious to one of ordinary skill in the art at the time the invention 
was made to XOR the data after the block algorithm, in addition to before, because this 
technique is not susceptible to meet-in-the-middle attack as taught by Schneier (Page 367). 

Referring to claim 7, Rogaway discloses that the corresponding block of the generated 
value is generated based on the XOR of an encrypted nonce (Page 5, R) and an encrypted value 
(Page 5, L), which meets the limitation of the first/third mask value is computed by applying a 
XOR function to a first value derived from a nonce value and a second value derived from 
encrypting a third value using the block cipher and a key, wherein the second/fourth mask value 
is computed by applying a XOR function to a fourth value derived from the nonce value and a 
fifth value derived from encrypting a sixth value using the block cipher and a key. Rogaway does 
not specify that the key used to encrypt the value to generate the 'L' (Page 5) is different than the 
key used to encrypt M[i] ft? Z[i] (Page 5). However, it would have been obvious to one of 
ordinary skill in the art at the time the invention was made to use multiple keys in the encryption 
algorithm in order to enhance the strength of the encryption algorithm by making the algorithm 
more difficult to break. Using only a single encryption key is easier break than using multiple 
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because an attacker would only need to discover the one key as opposed to having to discover 
every key that is used in the encryption algorithm. Rogaway also does not disclose applying a 
substitution function to the result of the XOR function on L and R. However, it would have been 
obvious to one of ordinary skill in the art at the time the invention was made to perform a 
substitution function on the result of the XOR function on L and R because substitution 
operations are an important part of block cipher algorithms that give them security as taught by 
Schneier (Page 275). 

Referring to claim 8, Rogaway describes the decryption process where cipherb locks are 
XOR'd with the corresponding block of the generated Z value (Page 5), which meets the 
limitation of whitening the at least one output ciphertext block with the second mask value. The 
result of the XOR function is decrypted with the key (Page 5), which meets the limitation of 
decrypting the at least one whitening ciphertext block using a block cipher and the first key. The 
decrypted value is then XOR's with the corresponding block of the generated Z value (Page 5), 
which meets the limitation of whitening the at least one decrypted block with a first mask value 
to generate at least one corresponding message block. 

Referring to claim 9, Rogaway discloses that the block cipher used is the AES block 
cipher (Page 6, first paragraph), which meets the limitation of the block cipher is AES. 

Referring to claim 10, Rogaway discloses that the L and R values are elements of the 
offset vector Z (page 5), which meets the limitation of the second and fifth values are elements of 
a vector. 

12. Claims 12-20 are rejected under 35 U.S.C. 103(a) as being unpatentable over Rogaway, 
in view of Schneier. 
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Referring to claims 12, 20, Rogaway discloses that each message blocks is concatenated 
(Page 5, checksum generation function), which meets the limitation of applying a XOR function 
to all message blocks of a message to compute a XOR-sum. The checksum is then XOR'd with 
Z[m] (Page 5, calculation of value T'), which meets the limitation of applying a third mask 
value to the XOR-sum. The result of the XOR function is then encrypted (Page 5, calculation of 
value 'T'), which meets the limitation of encrypting the masked XOR-sum using the block 
cipher and the first key. Rogaway does not disclose XOR'ing the result of the encryption with a 
value. However, it would have been obvious to one of ordinary skill in the art at the time the 
invention was made to XOR the data after the block algorithm, in addition to before, because this 
technique is not susceptible to meet-in-the-middle attack as taught by Schneier (Page 367). 

Referring to claim 13, Rogaway discloses that the corresponding block of the generated 
value is generated based on the XOR of an encrypted nonce (Page 5, R) and an encrypted value 
(Page 5, L), which meets the limitation of the first/third mask value is computed by applying a 
XOR function to a first value derived from a nonce value and a second value derived from 
encrypting a third value using the block cipher and a key, wherein the second/fourth mask value 
is computed by applying a XOR function to a fourth value derived from the nonce value and a 
fifth value derived from encrypting a sixth value using the block cipher and a key. Rogaway does 
not specify that the key used to encrypt the value to generate the 'L' (Page 5) is different than the 
key used to encrypt M[i] ft? Z[i] (Page 5). However, it would have been obvious to one of 
ordinary skill in the art at the time the invention was made to use multiple keys in the encryption 
algorithm in order to enhance the strength of the encryption algorithm by making the algorithm 
more difficult to break. Using only a single encryption key is easier break than using multiple 
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because an attacker would only need to discover the one key as opposed to having to discover 
every key that is used in the encryption algorithm. Rogaway also does not disclose applying a 
substitution function to the result of the XOR function on L and R. However, it would have been 
obvious to one of ordinary skill in the art at the time the invention was made to perform a 
substitution function on the result of the XOR function on L and R because substitution 
operations are an important part of block cipher algorithms that give them security as taught by 
Schneier (Page 275). 

Referring to claim 14, Rogaway discloses that to compute the R value, the nonce is 
XOR'd with L and the result of the XOR function is encrypted with key K (Page 5), which meets 
the limitation of the first and fourth values derived from the nonce value are permutations of a 
binary value computed by encrypting the nonce value using the block cipher and the first key. 

Referring to claims 15, 16, Rogaway discloses encrypting a message by exclusive or'ing 
a block of the message with a corresponding block of a generated value (Page 5, M[i] Z[i]), 
which meets the limitation of whitening at least one message block with a third mask value. The 
result of that exclusive or operation is encrypted (Page 5) using a block cipher (Page 4), which 
meets the limitation of encrypting the at least one whitened message block using a block cipher 
and a first key. The result of the encryption is the exclusive or'ed with a corresponding block of 
the generated value (Page 5), which meets the limitation of whitening the at least one encrypted 
message block with the third mask value to generate at least one corresponding output ciphertext 
block. 

Referring to claim 17, Rogaway discloses that the corresponding block of the generated 
value is generated based on the XOR of an encrypted nonce (Page 5, R) and an encrypted value 
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(Page 5, L), which meets the limitation of the first and second mask values are computed by 
applying a XOR function to a first value derived from a nonce value and a second value derived 
from encrypting a third value using the block cipher and a key. Rogaway does not specify that 
the key used to encrypt the value to generate the L' (Page 5) is different than the key used to 
encrypt M[i] © Z[i] (Page 5). However, it would have been obvious to one of ordinary skill in 
the art at the time the invention was made to use multiple keys in the encryption algorithm in 
order to enhance the strength of the encryption algorithm by making the algorithm more difficult 
to break. Using only a single encryption key is easier break than using multiple because an 
attacker would only need to discover the one key as opposed to having to discover every key that 
is used in the encryption algorithm. Rogaway also does not disclose applying a substitution 
function to the result of the XOR function on L and R. However, it would have been obvious to 
one of ordinary skill in the art at the time the invention was made to perform a substitution 
function on the result of the XOR function on L and R because substitution operations are an 
important part of block cipher algorithms that give them security as taught by Schneier (Page 
275). 

Referring to claim 18, Rogaway discloses that the block cipher used is the AES block 
cipher (Page 6, first paragraph), which meets the limitation of the block cipher is AES. 

Referring to claim 19, Rogaway discloses that the L and R values are elements of the 
offset vector Z (page 5), which meets the limitation of the second and fifth values are elements of 
a vector. 

Conclusion 
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13. Applicant's amendment necessitated the new ground(s) of rejection presented in this 
Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). 
Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). 

A shortened statutory period for reply to this final action is set to expire THREE 
MONTHS from the mailing date of this action. In the event a first reply is filed within TWO 
MONTHS of the mailing date of this final action and the advisory action is not mailed until after 
the end of the THREE-MONTH shortened statutory period, then the shortened statutory period 
will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 
CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, 
however, will the statutory period for reply expire later than SIX MONTHS from the date of this 
final action. 

14. Any inquiry concerning this communication or earlier communications from the 
examiner should be directed to BENJAMIN E. LANIER whose telephone number is (571)272- 
3805. The examiner can normally be reached on M-Th 6:00am-4:30pm. 

If attempts to reach the examiner by telephone are unsuccessful, the examiner's 
supervisor, Gilberto Barron can be reached on 571-272-3799. The fax phone number for the 
organization where this application or proceeding is assigned is 571-273-8300. 
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Information regarding the status of an application may be obtained from the Patent 
Application Information Retrieval (PAIR) system. Status information for published applications 
may be obtained from either Private PAIR or Public PAIR. Status information for unpublished 
applications is available through Private PAIR only. For more information about the PAIR 
system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR 
system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would 
like assistance from a USPTO Customer Service Representative or access to the automated 
information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. 



/Benjamin E Lanier/ 

Primary Examiner, Art Unit 2132 



